Skip to content
Noroxi

monstra records

43 published records for vendor monstra.

All records

43 records
  • Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (l

    HighCVSS 8.8WeaponizedEPSS 63%

    monstra · monstraJan 23, 2018

  • A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4

    CriticalCVSS 9.8No exploitEPSS 3%

    monstra · monstraOct 28, 2021

  • A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitr

    CriticalCVSS 9.8No exploitEPSS 2%

    monstra · monstraJun 17, 2021

  • plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.

    CriticalCVSS 9.8No exploitEPSS 2%

    monstra · monstra cmsJun 5, 2018

  • CVE-2018-6383
    39Monitor

    Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or .pha

    HighCVSS 8.8Proof of conceptEPSS 13%

    monstra · monstraJan 29, 2018

  • Monstra 3.0.4 does not filter the case of php, which leads to an unrestricted file upload vulnerability.

    CriticalCVSS 9.8No exploitEPSS 2%

    monstra · monstraJun 15, 2022

  • CVE-2018-9037
    36Monitor

    Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain

    HighCVSS 8.8No exploitEPSS 3%

    monstra · monstraApr 10, 2018

  • Monstra CMS 3.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via admin/index.php?id=filesmanager because, fo

    HighCVSS 8.8No exploitEPSS 3%

    monstra · monstraMay 22, 2020

  • Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit

    HighCVSS 8.8No exploitEPSS 2%

    monstra · monstra cmsJul 1, 2021

  • In Monstra CMS 3.0.4, an attacker with 'Editor' privileges can change the password of the administrator via an admin/index.php?id=users&acti

    HighCVSS 8.8No exploitEPSS 1%

    monstra · monstraSep 10, 2018

  • Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin.

    HighCVSS 8.8Proof of conceptEPSS 1%

    monstra · monstra cmsFeb 5, 2026

  • Monstra CMS 3.0.4 has a Session Management Issue in the Administrations Tab.

    HighCVSS 8.0No exploitEPSS 1%

    monstra · monstraMay 25, 2018

  • Monstra CMS 3.0.4 has a Session Management Issue in the Users tab.

    HighCVSS 8.0No exploitEPSS 1%

    monstra · monstraMay 25, 2018

  • admin/index.php in Monstra CMS 3.0.4 allows arbitrary directory listing via id=filesmanager&path=uploads/.......//./.......//./ requests.

    HighCVSS 7.5No exploitEPSS 2%

    monstra · monstraSep 18, 2018

  • CVE-2018-9038
    29Monitor

    Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.

    MediumCVSS 6.5Proof of conceptEPSS 9%

    monstra · monstraApr 10, 2018

  • Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP file

    HighCVSS 7.2Proof of conceptEPSS 3%

    monstra · monstraMar 7, 2019

  • Monstra CMS 3.0.4 does not properly restrict modified Snippet content, as demonstrated by the admin/index.php?id=snippets&action=edit_snippe

    HighCVSS 7.2No exploitEPSS 2%

    monstra · monstraSep 10, 2018

  • Monstra CMS 3.0.4 allows an attacker, who already has administrative access to modify .chunk.php files on the Edit Chunk screen, to execute

    HighCVSS 7.2No exploitEPSS 1%

    monstra · monstra cmsJun 9, 2020

  • An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

    HighCVSS 7.2No exploitEPSS 1%

    monstra · monstraJun 6, 2024

  • CVE-2020-8439
    26Monitor

    Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit U

    MediumCVSS 6.5No exploitEPSS 2%

    monstra · monstraMar 6, 2020

  • An issue in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via bypassing the file extension filter and uploadi

    MediumCVSS 6.5No exploitEPSS 1%

    monstra · monstra cmsSep 27, 2021

  • Monstra CMS 3.0.4 and earlier has XSS via index.php.

    MediumCVSS 6.1Proof of conceptEPSS 5%

    monstra · monstra cmsJul 3, 2019

  • Monstra CMS V3.0.4 allows HTTP header injection in the plugins/captcha/crypt/cryptographp.php cfg parameter, a related issue to CVE-2012-294

    MediumCVSS 6.1Proof of conceptEPSS 3%

    monstra · monstraSep 12, 2018

  • Monstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).

    MediumCVSS 6.1Proof of conceptEPSS 2%

    monstra · monstraMay 25, 2018

  • Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via t

    MediumCVSS 6.1No exploitEPSS 2%

    monstra · monstraAug 14, 2018